Senior Security GRC Lead

il y a 1 semaine


Luxembourg, Luxembourg Ant Group Temps plein

Description


Ant International strives to become the most trusted digital services connector to achieve sustainable growth of global commerce. With a focus on Travel, Trade, Technology, and Talent, Ant International is committed to enhancing the digital mindset and capacities of businesses worldwide. Through fostering collaborative efforts with partners, we are driving responsible innovation and increase market accessibility for global SMEs. In EMEA we do so across 3 key businesses: Alipay+, Antom and WorldFirst (Where you will partner as HRBP+ also). Team Introduction: We are seeking an experienced Senior Security GRC Lead to join our dynamic fintech team in Luxembourg. This critical role will be responsible for developing and maintaining our comprehensive information security governance, risk, and compliance framework in alignment with CSSF regulations, DORA requirements, and international standards. The successful candidate will play a pivotal role in ensuring our digital operational resilience and protecting our financial services infrastructure. This position provides dedicated security governance support with a 50/50 split between:

  • 50% supporting the EMEA regional team with security strategy, risk management, and security compliance initiatives
  • 50% supporting the local Luxembourg entity with CSSF regulatory compliance, DORA implementation, and local security operations
Key responsibilities: 1. Information Security Strategy & Governance
  • Develop and maintain the information security strategy, ensuring alignment with business objectives and regulatory requirements
  • Establish and oversee the information security governance framework, including policies, standards, and procedures
  • Lead the Information Security Committee and provide regular reporting to senior management
2. Regulatory Compliance Management
  • DORA Compliance: Ensure full compliance with the Digital Operational Resilience Act (DORA) requirements, including ICT risk management, incident reporting, digital operational resilience testing, and third-party risk management
  • CSSF Regulations: Maintain compliance with CSSF Circular 25/880 and other relevant Luxembourg financial regulations
  • Industry Standards: Ensure adherence to PSD2-SCA, PCI-DSS, SWIFT CSP, ISO27001, and other applicable financial industry standards
  • EBA (European Banking Authority) guidelines and technical standards
3. Risk Management Framework
  • Identify, assess, and prioritize security risks across the organization
  • Develop and implement comprehensive risk mitigation strategies and action plans
  • Conduct regular ICT risk assessments and oversee the annual Long Form Report preparation
  • Implement and maintain a robust third-party vendor security risk management program
4. Digital Operational Resilience
  • Design and implement the DORA-compliant ICT risk management framework
  • Plan and execute digital operational resilience testing programs, including threat-led penetration testing
  • Establish and maintain incident response capabilities aligned with DORA incident reporting requirements
  • Implement continuous security monitoring and threat detection capabilities
5. Security Architecture & Technology
  • Good understanding of Technology and Security architectural designs
  • Good understanding of SIEM, DLP, Endpoint Security
6. Security Awareness & Culture
  • Oversee and deliver Security awareness and training programs
  • Foster a security-conscious culture throughout the organization
  • Provide security guidance and support to business units and technical teams
7. Audit & Regulatory Engagement
  • Act as the primary contact point for IT security audits, inspections, and regulatory examinations
  • Coordinate responses to regulatory inquiries and implement corrective actions
  • Maintain relationships with CSSF and other regulatory authorities
Job requirements and expectations:
  • Experience: 5+ years in information security management roles as Security GRC Lead, or equivalent position in the financial services industry
  • Technical Background: Strong technical foundation in cloud security, IT infrastructure, and application security
  • Regulatory Expertise:
  1. DORA (Digital Operational Resilience Act) and its implementation requirements
  2. CSSF regulations, including Circular 25/880 on ICT security and risk management
  3. PSD2-SCA, PCI-DSS, SWIFT CSP, and other financial industry standards
  4. ISO27001 and NIST cybersecurity frameworks
Technical Skills
  • Cloud Security: Good background of Cloud Security controls and best practices
  • Security Technologies: Good Knowledge of SIEM, EDR, vulnerability management, and identity management solutions
  • Architecture: Understanding Security architectures
  • Emerging Technologies: Knowledge of AI security.
Professional Competencies
  • Leadership: Proven ability to lead security initiatives and influence stakeholders at all levels
  • Communication: Excellent presentation and communication skills, with experience presenting to Risk Management Committees, Board of Directors, and regulatory bodies
  • Problem-Solving: Strong analytical and decision-making abilities in complex regulatory environments
  • Project Management: Experience managing security projects and compliance initiatives


  • Luxembourg, Luxembourg SkillHubs Temps plein

    Join a global leader in Biopharma on a strategic cybersecurity program covering two production sites in Southern Europe.As Senior Cyber Security Consultant, you will work as an independent expert, supporting corporate and site security teams to strengthen the protection of OT, IT, and BMS systems in accordance with global governance and regulatory...

  • Senior Security Monitoring

    il y a 2 semaines


    Luxembourg, Luxembourg Arendt & Medernach Temps plein

    Arendt is your legal, tax and business services firm in Luxembourg.At Arendt we combine the entire value chain of services dedicated to asset managers, banks, insurers, public institutions, commercial companies and private clients operating in Luxembourg.Arendt offers specialist advice, that encompasses all legal, regulatory, taxation and advisory aspects of...

  • Senior Security Officer

    il y a 2 semaines


    Luxembourg, Luxembourg RTL Group BCE Temps plein

    Broadcasting Center Europe (BCE) is a European leader in media services, system integration and software development in the areas of television, radio, production and postproduction, telecommunication and IT.With its extensive experience on the media market, our team provides high-quality services, supporting our customers in their development.With more than...


  • Luxembourg, Luxembourg Arendt Temps plein

    Arendt & Medernach is the leading independent business law firm in Luxembourg with over 800 professionals. The firm's international team of more than 450 legal experts represents Luxembourg and foreign clients in all areas of Luxembourg business law from its main office in Luxembourg and representative offices in Frankfurt, Hong Kong, London, New York, and...


  • Luxembourg, Luxembourg Julius Baer Temps plein

    At Julius Baer, we celebrate and value the individual qualities you bring, enabling you to be impactful, to be entrepreneurial, to be empowered, and to create value beyond wealth. Let's shape the future of wealth management together. The CISO Europe Hub is a senior leadership role responsible for defining and executing the regional Information & Cyber...


  • Luxembourg, Luxembourg TMC Temps plein

    Luxembourg Digital & IT Luxembourg, Luxembourg HybridTMC Luxembourg is looking for a System and Security Technical Lead (M/F) for one of its clients.About The Member CompanyWe are a global high-tech consultancy company with a team of entrepreneurial engineers, scientists, and digital experts from around the world. Together we form a fast-growing and proud...


  • Luxembourg, Luxembourg SEO (Société Electrique de l'Our) Temps plein

    Die Société Electrique de l'Our (SEO) betreibt das Pumpspeicherkraftwerk in Vianden, das ein integraler Bestandteil des europäischen Verbundsystems ist. Das Kraftwerk leistet einen bedeutenden Beitrag zur Leistungs- und Frequenzregelung sowie zur Spannungsstabilisierung im europäischen Stromnetz. Dank seiner hohen Verfügbarkeit stellt es zudem eine...

  • Senior Sales Lead

    il y a 1 semaine


    Luxembourg, Luxembourg Deutsche Börse Group Temps plein

    Your area of workAs part of the Eurex Sales team, you will play a key role in driving client engagement and revenue growth across a broad range of asset classes, including equity index derivatives, repo, fixed income, and OTC interest rate derivatives. This sales role is focused on building and deepening strategic client relationships, identifying new...

  • Security Manager

    il y a 2 semaines


    Luxembourg, Luxembourg Pinkerton Temps plein

    Overview170+ Years Strong. Industry Leader. Global Impact.At Pinkerton, the mission is to protect our clients. To do this, we provide enterprise risk management services and programs specifically designed for each client. Pinkerton employees are one of our most important assets and critical to the delivery of world-class solutions. Bonded together, we share...


  • Luxembourg, Luxembourg Qualco Temps plein

    At Quento, the ICT arm of the Qualco Group, we deliver comprehensive and innovative solutions across AI, Digital Engineering, Cloud, and Cybersecurity, helping businesses accelerate digital transformation. With a presence in Greece, Luxembourg, and Belgium, and backed by the expertise of the Qualco Group, we combine deep technical knowledge with strategic...